A newly discovered data leak in the AsusWRT, a web-based GUI app from Asus that allows users to manage their wifi network. AsusWRT becomes a centralized access point for all internet devices such as phones, tablets, or laptops connected to the network, and for smart devices and Amazon Alexa products. Researchers discovered that hackers could access AsusWRT users’ IP Address, name, device name, usage information, location and other data, and Alexa user behavioral data.

Experts Comments

November 06, 2019
James McQuiggan
Security Awareness Advocate
KnowBe4
The ASUSWRT application is used by Asus routers to manage private wifi networks of the user. Alexa products are impacted if they have one connected to the Asus router along with any other computers or IoT (internet of things) devices like smart door locks or smart TVs. This is concerning, as it is unknown if this has been used by bad actors and if they\'ve stolen the databases which contains IP address, device names (i.e. John\'s phone), GPS locations, location information and logging.....Read More
The ASUSWRT application is used by Asus routers to manage private wifi networks of the user. Alexa products are impacted if they have one connected to the Asus router along with any other computers or IoT (internet of things) devices like smart door locks or smart TVs. This is concerning, as it is unknown if this has been used by bad actors and if they\'ve stolen the databases which contains IP address, device names (i.e. John\'s phone), GPS locations, location information and logging information from the attached devices. Using internet scanning tools, the hackers can search for the ASUS routers and exploit them to steal the information. The bad actors could also use the information to access the private network and take control of the computers, the smart TV\'s or smart door locks. Additionally, the information can be used to craft spearphishing emails to the consumers and get them to click on a link or open an attachment to download malware and infect their home computers. Consumers who use this ASUSWRT application need to be aware that their information has been exposed and they should take mitigating steps to protect themselves from spearphishing attacks. Consumers should check the manufacturer\'s website for a software update that patches the system and disable the ASUSWRT in the meantime.  Read Less
November 06, 2019
Jelle Wieringa
Technical Evangelist
KnowBe4
It was only a matter of time for something like this to happen. The router plays a central role in most home networks, and if this gets compromised, we shouldn't be surprised that a connected smart device like an Amazon Alexa is a good target. With all these connected and smart devices in the home today, we need to be even more vigilant when it comes to our security. Understand that everything you do in your home might be recorded.
What do you think of the topic? Do you agree with expert(s) or share your expert opinion below.
Be part of our growing Information Security Expert Community (1000+), please register here.